VYPR
Medium severity6.1NVD Advisory· Published Nov 18, 2020· Updated Jun 17, 2026

CVE-2020-26884

CVE-2020-26884

Description

RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application.

Affected products

4
  • Rsa/Archer3 versions
    cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*range: >=6.8,<=6.8.0.3
    • cpe:2.3:a:rsa:archer:6.9:*:*:*:*:*:*:*
    • (no CPE)range: 6.8 through 6.8.0.3 and 6.9
  • RSA/Archerdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.